#Internal #NDA

Effective date: August 1, 2026

6.1 Applicability

This policy applies to all employees, co-founders, interns, contractors, and freelancers ("Personnel") who have access to Hirfa's internal systems, source code, or confidential information, regardless of employment classification.

6.2 Confidentiality Obligations

Every member of Personnel must execute a Non-Disclosure Agreement ("NDA") prior to being granted any system access. The NDA covers:

  • Trade secrets: business model details, financial projections, fundraising materials, and go-to-market/geographic expansion strategy.
  • User data: any personal data belonging to Clients or Craftsmen, regardless of data classification level.
  • Source code and architecture: the Platform's codebase, infrastructure design, and security controls.
  • Unreleased product plans: features, pricing changes, or partnerships not yet publicly announced.

6.3 Duration of Confidentiality

Confidentiality obligations remain in effect for the full duration of the engagement with Hirfa and for a minimum of three (3) years following termination, regardless of the reason for termination (resignation, dismissal, or contract expiry).

6.4 Intellectual Property Assignment

All work product — code, designs, documentation, or other creative or technical output — produced by Personnel in connection with their engagement with Hirfa, or using Hirfa's resources, is deemed work made for hire and is the exclusive property of HIRFA LLC, except where a separate written agreement explicitly states otherwise.

6.5 System Access and Offboarding

  • Personnel are granted system access strictly according to the Least Privilege principle defined in the Access Control Policy (Section 8).
  • Upon termination of engagement for any reason, all system access, credentials, and physical/company assets must be revoked and returned on the last day of engagement, following the formal Offboarding Checklist.

6.6 Acceptable Device and Network Use

  • Devices and accounts used to access Hirfa systems must be protected with a strong password/passphrase and mandatory two-factor authentication.
  • Access to production systems over unsecured public Wi-Fi networks is prohibited without an approved VPN connection.
  • Personnel must not store confidential Hirfa data on personal, unmanaged devices or personal cloud storage accounts.

6.7 Reporting Obligations

Personnel who become aware of a security incident, policy violation, or suspected breach of confidentiality — by themselves or others — are obligated to report it immediately to security@gethirfa.com, without fear of retaliation for good-faith reporting.